See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Known exploited

31–45 of 213 matching entries · 2884 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-59822KEVBerriAI LiteLLM Improper Authentication Vulnerability0.01 Sep 202622:00 UTCLiteLLMSee original advisory50 sourcesNoneYesCVE-2026-59310KEVBroadcom VMware vCenter Path Traversal Vulnerability0.017 Aug 202622:00 UTCVMware vCenterSee original advisory2 sourcesNoneYesCVE-2026-58704KEVGoogle Pixel Improper Authorization Vulnerability0.015 Sep 202622:00 UTCPixelSee original advisory3 sourcesNoneYesCVE-2026-58644KEVMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability0.015 Jul 202622:00 UTCSharePointSee original advisory2 sourcesNoneYesCVE-2026-56155KEVMicrosoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability0.013 Jul 202622:00 UTCActive Directory Federation ServicesSee original advisory2 sourcesNoneYesCVE-2026-55040KEVMicrosoft SharePoint Weak Authentication Vulnerability0.026 Aug 202608:15 UTCSharePointSee original advisory404 sourcesVerifiedYesCVE-2026-53362KEVLinux Kernel Unspecified Vulnerability0.026 Aug 202622:00 UTCKernelSee original advisory96 sourcesCandidateYesCVE-2026-50522KEVMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability0.021 Jul 202622:00 UTCSharePointSee original advisory2 sourcesNoneYesCVE-2026-49869KEVKestra OSS OS Command Injection Vulnerability0.01 Sep 202622:00 UTCKestra OSSSee original advisory93 sourcesVerifiedYesCVE-2026-48907KEVWidget Factory Joomla Content Editor Improper Access Control Vulnerability0.026 Aug 202612:34 UTCJoomla Content EditorSee original advisory1187 sourcesVerifiedYesCVE-2026-48710KEVKludex Starlette HTTP Request/Response Smuggling Vulnerability0.01 Sep 202622:00 UTCStarletteSee original advisory270 sourcesVerifiedYesCVE-2026-46817KEVOracle E-Business Suite Improper Privilege Management Vulnerability0.014 Jul 202622:00 UTCE-Business SuiteSee original advisory2 sourcesNoneYesCVE-2026-45659KEVMicrosoft SharePoint Server Deserialization of Untrusted Data Vulnerability8.811 Sep 202613:02 UTCSharePoint ServerSee original advisory46 sourcesCandidateYesCVE-2026-42897KEVMicrosoft Exchange Server Cross-Site Scripting Vulnerability8.115 Sep 202610:56 UTCMicrosoftSee original advisory22 sourcesCandidateYesCVE-2026-42018KEVartifactory vulnerability7.512 Sep 202602:16 UTCartifactorybefore 7.111.20 (custom); 7.117.0 through before 7.117.27 (custom); 7.125.0 through before 7.125.19 (custom); 7.133.0 through before 7.133.28 (custom); 7.146.0 through before 7.146.8 (custom)22 sourcesNoneYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.